SCCs, the Data Privacy Framework, and What Survives Schrems III
If you run a digital agency or small business in the European Union, your daily operations rely on a sprawling, interconnected web of software-as-a-service (SaaS) tools. You likely use Mailchimp to send newsletters, HubSpot to manage your sales pipeline, Google Workspace for documents, Amazon Web Services (AWS) for hosting, and Slack for internal communications. These platforms enable unprecedented productivity, but because the vast majority of them are headquartered in the United States, they also introduce severe, systemic compliance risks under European data protection laws.
This is not a theoretical legal history lesson. It is a practical reality. The mechanisms you rely on today are under active threat, and if they collapse, your agency could lose its legal basis for using its entire software stack overnight. This guide breaks down exactly why transferring data to the US is so complicated, explains the two mechanisms keeping your operations legal today, and outlines the practical steps you must take to protect your business regardless of what the courts decide next.
1. Why Transferring Data to the US Is a Problem at All
To understand the risk, you have to understand the fundamental mismatch between how the European Union and the United States view privacy. The EU treats data protection as a fundamental human right, enforcing strict regulatory oversight through the General Data Protection Regulation (GDPR). Chapter V of the GDPR explicitly restricts the transfer of personal data outside the European Economic Area (EEA) unless the destination country has an "adequate" legal mechanism that guarantees GDPR-equivalent protections.
The problem is that the United States does not have a comprehensive, EU-equivalent federal privacy law. Instead, the US relies on a fragmented system of state laws, while simultaneously granting its national security and law enforcement agencies incredibly broad, extraterritorial surveillance powers. Two specific US laws create massive headaches for EU businesses:
- FISA Section 702: The Foreign Intelligence Surveillance Act allows US intelligence agencies, such as the NSA and FBI, to collect the communications data of non-US citizens located abroad without needing an individualized judicial warrant. This operates as a bulk, program-level intelligence-gathering mechanism that targets the exact data your agency might store on US servers.
- The CLOUD Act: Passed in 2018, the Clarifying Lawful Overseas Use of Data Act establishes that legal jurisdiction follows the corporate entity, not the physical server. This means that if you use a US-controlled cloud provider—like Google, AWS, or Slack—the US government can compel that company to produce your data, even if your data is physically stored in a secure data center in Frankfurt, Dublin, or Paris.
Because these US surveillance orders often come with gag orders, your vendor is legally prohibited from telling you that your European clients' data was handed over to the US government. This creates a direct conflict with the GDPR, which forbids transferring personal data to foreign authorities solely on the basis of a foreign court order.
2. The Two Current Legal Mechanisms Keeping You Afloat
Because cutting off all digital trade between the EU and the US would be economically disastrous, negotiators have built legal bridges to bypass these surveillance conflicts. Today, your agency's use of US SaaS tools relies on two primary mechanisms:
Standard Contractual Clauses (SCCs)
Standard Contractual Clauses are pre-approved, standardized contract templates issued by the European Commission. When you sign a software agreement with a US vendor, you are usually signing SCCs. By signing these templates, both you (the data exporter) and your US vendor (the data importer) enter into a legally binding bilateral contract guaranteeing that the personal data will be handled according to strict European standards.
The EU-US Data Privacy Framework (DPF)
The Data Privacy Framework is an adequacy agreement adopted by the European Commission in July 2023. It acts as a blanket approval for specific US companies. Under the DPF, the EU essentially declared that if a US company self-certifies its compliance with a specific set of privacy principles through the US Department of Commerce, that company provides an "adequate" level of protection. If a vendor is DPF-certified, you can freely transfer EU data to them without needing to implement additional contractual safeguards.
Because relying on just one of these mechanisms is risky, most major US SaaS providers employ a "belt-and-suspenders" approach. Platforms like AWS, Google Cloud, and HubSpot maintain active DPF certifications while simultaneously embedding SCCs into their standard Data Processing Agreements. This redundancy ensures that if one mechanism fails, the other acts as a safety net.
3. Why Both Mechanisms Are Incredibly Fragile
If you look at the history of transatlantic data transfers, it is a cycle of political negotiation, lawsuits, and sudden collapse. The DPF is actually the European Commission's third attempt to build a bridge. Its two predecessors—Safe Harbor and the Privacy Shield—were both struck down by the Court of Justice of the European Union (CJEU) following lawsuits led by Austrian privacy lawyer Max Schrems. Safe Harbor fell in 2015 (a case known as Schrems I), and Privacy Shield fell in 2020 (Schrems II) because the courts found that US surveillance laws violated European fundamental rights.
Today, the Data Privacy Framework and your SCCs are facing severe threats on multiple fronts:
The Fall of FTC Independence (Trump v. Slaughter)
The DPF's legal survival depends on the US providing independent regulatory oversight. In its 2023 approval of the DPF, the European Commission cited the "independent" authority of the US Federal Trade Commission (FTC) 259 times as the primary enforcer of these privacy rules.
However, on June 29, 2026, the US Supreme Court issued a landmark 6-3 ruling in Trump v. Slaughter. The court ruled that the FTC is not actually independent; because it exercises executive power, the US President can fire FTC commissioners at will, for any reason. By stripping the FTC of its statutory independence, the US Supreme Court accidentally knocked out the foundational pillar of the EU-US Data Privacy Framework.
The NOYB Challenge and Schrems III
Max Schrems’ privacy advocacy group, NOYB, reacted to the Supreme Court decision within 24 hours. NOYB has formally petitioned the European Commission to repeal the DPF and is preparing a lawsuit to strike it down at the CJEU. Legal experts universally refer to this pending challenge as Schrems III. Given the CJEU's history of invalidating previous agreements, it is highly realistic that the DPF will be destroyed.
The SCC Transfer Impact Assessment (TIA) Trap
You might think that if the DPF dies, your SCCs will save you. But SCCs have a massive catch. While they survived Schrems II, the CJEU ruled that you cannot blindly sign them. If you use SCCs, you must conduct a Transfer Impact Assessment (TIA) to prove that the destination country's laws (i.e., US surveillance laws) do not prevent the vendor from actually honoring the contract.
Given that the US CLOUD Act explicitly overrides contractual privacy commitments and forces providers to hand over data, completing an honest TIA that concludes your data is safe in the US is practically impossible without applying heavy, complex encryption.
4. What "Schrems III" Means Practically for Your Business
When courts strike down these agreements, they do not offer multi-year grace periods. When the Privacy Shield was invalidated in 2020, the legal basis for thousands of data transfers vanished overnight.
If Schrems III successfully invalidates the DPF, any US SaaS tool in your tech stack that relies solely on its DPF certification will instantly lose its legal basis to process your clients' European personal data.
Because the average modern agency uses between 15 and 30 integrated US-controlled tools—spanning CRM, email marketing, analytics, and project management—your operational exposure is systemic. Continuing to use these tools without a valid legal mechanism exposes your business to regulatory investigations, fines under the GDPR, and civil lawsuits from data subjects. Following the last major ruling, privacy groups targeted dozens of EU websites using US-based analytics, forcing regulators to issue fines and ban specific integrations. A Schrems III ruling would result in a similar operational disruption for organizations unprepared for the change.
5. What to Do Now: Your Practical Preparedness Checklist
You cannot wait for a court ruling to start fixing your tech stack. Waiting until the DPF is invalidated means scrambling to rewrite contracts and migrate databases while actively violating the law. You must build resilience into your vendor management processes today.
Here is your practical, step-by-step checklist to insulate your agency:
- Audit Your Vendor Stack and Document Everything: You cannot manage what you have not mapped. Audit every third-party software tool your agency uses and identify exactly which transfer mechanism it relies on (DPF, SCCs, or both). You must track these details systematically in your Record of Processing Activities; you can use our practical ROPA template to structure this inventory so it is ready for any regulatory inspection.
- Deploy Automated Vendor Monitoring: Tracking the compliance status of 30 different software vendors manually is a recipe for failure. Custodia’s vendor intelligence module continuously monitors sub-processor transfer mechanisms and flags dependencies that rely solely on the DPF so you know which vendors need SCCs as fallback.
- Ensure SCCs Are Your Contractual Backstop: Do not allow any critical US vendor to rely solely on the Data Privacy Framework. You must execute or re-paper your vendor agreements to ensure that Standard Contractual Clauses are embedded as a fallback mechanism. If the DPF falls, your SCCs will ensure your data flow does not immediately become illegal, giving you time to react.
- Run Transfer Impact Assessments (TIAs): For your critical US vendors relying on SCCs, you must complete a Transfer Impact Assessment. Your TIA must honestly acknowledge US surveillance laws (FISA 702 and the CLOUD Act) and document the specific technical safeguards you have in place to prevent unauthorized access.
- Consider EU-Hosted Alternatives for Sensitive Data: You must separate your data by sensitivity. While basic marketing assets can likely remain on US platforms with SCCs, highly sensitive data (health data, financial records, HR files) should not live on US-controlled infrastructure. Consider migrating your most critical processing activities to fully sovereign European cloud alternatives that do not have a US parent company.
For a deeper understanding of how these vendor management requirements fit into your broader liability as a data controller or processor, refer to our GDPR compliance guide for agencies.
Conclusion
The constitutional shift initiated by the US Supreme Court has severely compromised the legal foundations of EU-US data transfers. Prudent agency operators must stop treating DPF adequacy as a permanent, unbreakable compliance shield. By auditing your vendors, implementing SCCs, and running honest risk assessments today, you can protect your operations from the inevitable fallout of a Schrems III ruling.
Do not wait for a compliance crisis to evaluate your tech stack. Discover your direct exposure and establish immediate compliance resilience by taking our free gap assessment.
Find out your GDPR score
Take our free 12-minute assessment to see where your agency stands.
Take free assessment